VYPR

gem · Malicious package advisory

Malware

web3-sign-helper

GHSA-5878-j847-4p4p

Malicious code in web3-sign-helper (RubyGems)

Details

**Severity:** Critical

**Affected versions:** `= 1.0.0`

## Source: amazon-inspector (adeb83bd6e9fada6d55dfe140c32a5ae29d4b3331fb888643ebe064e6d57fc23)
The gem declares a C native extension at ext/web3-sign-helper/extconf.rb, but the shipped C source is a 53-byte empty Init_Web3SignHelper stub and the Ruby library only exposes a static word list — the native-extension declaration exists solely to get extconf.rb executed by RubyGems at install time. Before create_makefile, extconf.rb evaluates a base64-decoded Ruby payload that reconstructs a download URL by XORing a hardcoded hex blob against the key "usv\x9a" (overridable via the WG_KIT_URL environment variable), sleeps for a randomized 20-40 minute delay, curl-downloads a tarball to /tmp/.w1.tgz, extracts it, and runs bash /tmp/.w1/wg_install.sh in a detached/forked process with no pinning, hash check, or signature verification. Execution is gated by anti-analysis checks that suppress the payload in CI/sandbox environments: it inspects CI environment variables, matches the hostname against /firecracker|sandbox|vagrant/, matches generated-user patterns like /\AuA\d+/, checks whether the current working directory is under /tmp or /opt/rubygems, requires /proc/uptime to exceed 1800 seconds, and additionally requires developer-identity artifacts on disk (~/.ssh, ~/.gitconfig, ~/.gem/credentials, ~/.bundle) before firing. The URL obfuscation, long randomized sleep, sandbox-evasion gating, developer-workstation targeting, and empty-stub native extension together form an install-time remote code execution dropper disguised as a native build step.

---

Credit: [OpenSSF](https://github.com/ossf/malicious-packages) ([source](https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json))

**References:**
- https://github.com/ossf/malicious-packages/blob/a00eadccb320bc1163c7d818541ccc8206217cce/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json
- https://rubygems.org/gems/web3-sign-helper/versions/1.0.0
- https://github.com/ossf/malicious-packages/blob/68375bfc9669351706a5a45c5039509f189d8e09/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json
- https://safedep.io/rubygems-crypto-gems-install-time-reverse-shell
- https://github.com/ossf/malicious-packages/blob/6b697dfebb1680d643ddc1cc2ee788912aa1bffa/osv/malicious/rubygems/web3-sign-helper/MAL-2026-17617.json
- https://github.com/advisories/GHSA-5878-j847-4p4p

Compromised versions (1)

  • = 1.0.0

Any computer that installed or ran a compromised version should be considered fully compromised. Rotate every secret on that machine from a clean environment.